Privacy Policy

Effective date: May 29, 2026  ·  Last updated: May 29, 2026

This Privacy Policy explains how KynectLocal ("we," "us," or "our") collects, uses, discloses, and safeguards information about users of the KynectLocal franchise management platform, including its web application, APIs, and associated services. Please read it carefully.

Contents

  1. Who We Are
  2. Scope and Applicability
  3. Data We Collect
  4. How We Use Your Data
  5. Legal Basis for Processing (GDPR)
  6. Third-Party Services and Sub-Processors
  7. Cookies and Tracking Technologies
  8. Franchise and Multi-Tenant Data Handling
  9. Artificial Intelligence Features
  10. Disclosure and Sharing of Data
  11. Data Retention
  12. Security Measures
  13. International Data Transfers
  14. Your Rights
  15. California Privacy Rights (CCPA / CPRA)
  16. Children's Privacy
  17. Changes to This Policy
  18. Contact Us

1. Who We Are

KynectLocal operates a multi-tenant Software-as-a-Service platform that enables franchise brands to manage their locations, digital presence, marketing content, lead generation, and operational workflows. The platform serves three categories of users: platform administrators, brand administrators, and franchisee operators.

For the purposes of applicable data protection laws, KynectLocal acts as a data controller with respect to account and platform-usage data, and as a data processor with respect to personal data submitted by customers, leads, and end users on behalf of the brands and franchisees that use our platform.

2. Scope and Applicability

This policy applies to:

  • Individuals who create or access a KynectLocal account (brand admins, franchisees, marketing users, platform admins).
  • Visitors and end users of public-facing pages and forms hosted through the KynectLocal platform on behalf of brands and franchisees.
  • Individuals whose data is submitted to the platform via web forms, lead capture, integration syncs (e.g., CallRail, WhatConverts, HubSpot), or API calls.

If you are a franchisee or brand operator using KynectLocal to collect data from your own customers, you bear independent responsibilities as a data controller for that data. This policy does not replace or override the privacy policies of the brands or franchisees operating on our platform.

3. Data We Collect

3.1 Account and Identity Data

  • Full name, email address, and hashed password.
  • Role and permission assignments (e.g., brand_admin, franchisee, marketing).
  • Profile information: phone number, job title, avatar image URL.
  • Invitation metadata: inviter identity, invitation acceptance timestamp, temporary password state.
  • Last login timestamp and account status (active, suspended).

3.2 Business and Location Data

  • Business name, address, city, state, zip code, country.
  • Business phone numbers, website URLs, and social media handles.
  • Operating hours, holiday hours, service descriptions, and staff information.
  • Location-specific SEO metadata: meta titles, descriptions, canonical URLs, Open Graph images.
  • Custom fields defined by brand administrators and values submitted by franchisees.
  • Latitude, longitude, and geographic coverage zones.

3.3 Content and Media Data

  • Page content, blocks, and layouts created or edited in the visual page builder.
  • Blog posts, events, and scheduled publications.
  • Media files uploaded to the platform (images, documents) stored via the configured storage provider.
  • Email templates, form definitions, and automated response configurations.
  • Content tokens and dynamic variable values used in page and email rendering.

3.4 Lead and Form Submission Data

  • Name, email, phone number, and any other fields included in form submissions.
  • UTM parameters, referrer URLs, and source attribution data captured at submission time.
  • Lead quality scores, call tracking data, and conversion events synced from integrated providers.
  • External lead identifiers from connected platforms (e.g., CallRail, WhatConverts).

3.5 Usage and Technical Data

  • IP addresses, browser type, and device information logged on each API request.
  • Request path, HTTP method, response status, and response time (via structured request logs).
  • Audit log entries: who did what to which resource, and when.
  • AI usage logs: prompt category, token counts, and model used (not prompt content).
  • Job queue events: bulk import progress, distribution sync outcomes, email delivery status.

3.6 Billing and Payment Data

  • Subscription plan, billing cycle, and license tier (Core, Pro, Enterprise).
  • Stripe customer and subscription identifiers. Payment card details are handled entirely by Stripe and are never stored on KynectLocal servers.
  • Invoice history, usage meter readings (AI tokens, distribution calls, API requests, storage).
  • Entitlement overrides and add-on configurations set by platform administrators.

3.7 Integration Credential Data

  • API keys, OAuth tokens, and webhook secrets for connected third-party services (e.g., HubSpot, Calendly, Google Business Profile, Yext, Meta Ads, TikTok Ads, Microsoft Ads, BrightLocal, Soci, CallRail, WhatConverts).
  • Integration credentials are stored encrypted at rest using AES-256-GCM.

4. How We Use Your Data

PurposeData Used
Authenticating users and maintaining secure sessionsEmail, hashed password, JWT tokens, refresh token chain
Providing platform features: page builder, content management, SEO tools, analyticsAccount data, business/location data, content data
Routing public web traffic to the correct brand or location pageDomain names, slug configuration, URL policy settings
Rendering and serving public-facing pages and sitemapsContent items, location profiles, media files, SEO metadata
Processing and routing lead submissionsForm submission data, lead data, integration push configurations
Sending transactional and marketing emails on behalf of brandsLead data, email template content, Resend API credentials
Syncing data with connected integrationsLead data, location data, integration credentials
Generating AI-assisted content suggestionsBusiness profile data, service descriptions, prompt context
Billing and subscription managementStripe identifiers, plan data, usage meters
Platform security, fraud prevention, and abuse monitoringIP addresses, request logs, audit log data
Improving platform reliability and diagnosing errorsRequest logs, error traces, job queue events
Complying with legal obligationsAny data required by applicable law

5. Legal Basis for Processing (GDPR)

For users in the European Economic Area, United Kingdom, and Switzerland, we rely on the following legal bases:

  • Contract performance — processing necessary to provide the platform services you have subscribed to.
  • Legitimate interests — security monitoring, fraud prevention, platform analytics, product improvement, and audit logging, where these interests are not overridden by your rights.
  • Legal obligation — processing required to comply with applicable law, including tax and financial record-keeping obligations.
  • Consent — where we specifically request your consent (e.g., optional analytics tracking). You may withdraw consent at any time.

For lead and form submission data processed on behalf of brands and franchisees, the applicable legal basis is determined by and the responsibility of the brand or franchisee acting as data controller.

6. Third-Party Services and Sub-Processors

KynectLocal engages the following categories of sub-processors. We require all sub-processors to maintain appropriate security and privacy standards.

ProviderCategoryPurpose
RailwayCloud infrastructureHosting API servers, worker processes, and managed PostgreSQL / Redis instances
Amazon S3 (via Railway)Object storageMedia file storage and static asset hosting
StripePayment processingSubscription billing, invoicing, and payment card handling
ResendEmail deliveryTransactional emails (invitations, password resets, billing notifications, lead notifications, broadcast emails)
Google Gemini (via Google AI)Artificial intelligenceAI-assisted content generation, SEO suggestions, and analytics chat interface
HubSpotCRM integration (optional)Pushing lead contact records to connected HubSpot accounts on behalf of brands
CalendlyScheduling integration (optional)Embedding booking widgets on location pages
CallRailCall tracking (optional)Syncing call lead data to the platform on behalf of connected brands
WhatConvertsLead tracking (optional)Syncing conversion lead data to the platform on behalf of connected brands
Google Business Profile / Yext / Soci / BrightLocalDistribution (optional)Distributing location data to directories and listing platforms (stub integrations)
Meta Ads / TikTok Ads / Microsoft AdsAdvertising pixels (optional)Injecting pixel tracking scripts on public pages on behalf of brands
MatomoWeb analytics (optional)On-premise or cloud analytics tracking on public pages on behalf of brands; configured per brand
ioredis / Redis (BullMQ)Job queueBackground job processing for imports, distribution, email, and usage aggregation

Optional integrations (marked above) are only active for brands that have explicitly configured and enabled them. Data is not sent to optional third parties unless that integration is active for the relevant brand or location.

7. Cookies and Tracking Technologies

7.1 Platform Application Cookies

The KynectLocal admin application uses session and authentication cookies to maintain logged-in state. These are strictly necessary and cannot be disabled while using the platform.

7.2 Public-Facing Pages

Pages published through KynectLocal on behalf of brands may set cookies depending on the integrations configured by the brand:

  • Matomo analytics — sets first-party analytics cookies if Matomo is configured for the brand. The specific cookies depend on the brand's Matomo configuration.
  • Meta Pixel / TikTok Pixel / Microsoft Advertising — if enabled by the brand, these third-party pixels set tracking cookies subject to the respective provider's privacy policies.
  • Calendly — if a Calendly embed is placed on a page, Calendly may set cookies per its own privacy policy.

Cookie consent management for public-facing pages is the responsibility of the brand or franchisee operating those pages. Brands are required to implement appropriate consent mechanisms in jurisdictions where consent is required.

7.3 Do Not Track

We honor Do Not Track browser signals within our own platform analytics. We do not control whether third-party pixels configured by brands honor Do Not Track signals.

8. Franchise and Multi-Tenant Data Handling

KynectLocal is a multi-tenant platform. Each tenant (brand) operates in a logically isolated data environment. All database queries are scoped by tenantId, and cross-tenant data access is prevented at the application layer.

8.1 Brand and Franchisee Relationship

Brand administrators set governance rules that determine which profile fields franchisees can edit independently versus fields that are locked at the brand level. KynectLocal enforces these rules but does not independently determine governance policy — that is set by each brand.

8.2 Location Data

Location data (address, hours, services, contact details, custom fields) is associated with the brand's tenant and is accessible to brand administrators. Franchisees can access only the locations they are explicitly assigned to.

8.3 Platform Administrator Access

KynectLocal super administrators have the technical ability to access all tenant data for the purposes of platform support, security incident investigation, and legal compliance. Such access is logged in the audit trail.

8.4 Data Isolation on Suspension or Termination

When a brand account is suspended, user access is revoked immediately. Data is not automatically deleted and may be retained for the period described in Section 11 (Data Retention) to allow for account recovery or legal compliance.

9. Artificial Intelligence Features

KynectLocal uses Google Gemini (gemini-2.5-flash) to power AI-assisted features including:

  • SEO content generation (meta titles, descriptions, llms.txt)
  • Service description generation
  • Page content suggestions via the Puck editor AI Assist
  • The analytics AI chat assistant

9.1 Data Sent to AI Providers

When you use an AI feature, relevant context from your account — such as business name, location, service descriptions, and analytics summaries — is included in the prompt sent to Google Gemini. We do not send payment card data, integration API keys, or end-user personal data (such as lead contact details) to AI providers.

9.2 AI Usage Logging

We log each AI call including: the brand and user who initiated it, the prompt category, the model used, and token counts. Actual prompt and response content is not stored in our logs.

9.3 AI-Generated Content

AI-generated content is a suggestion only. You are responsible for reviewing, editing, and publishing any content generated through AI features. We make no warranties regarding the accuracy, completeness, or suitability of AI-generated output.

9.4 AI Token Limits

AI feature usage is subject to the token limits of your license tier (Core: 10,000 tokens/month; Pro: 100,000 tokens/month; Enterprise: unlimited). Usage is tracked per brand.

10. Disclosure and Sharing of Data

We do not sell personal data. We do not share personal data with third parties for their independent marketing purposes. We disclose data only in the following circumstances:

  • Sub-processors — as described in Section 6, to provide platform functionality.
  • Franchise inquiries — If you identify your organization as a franchise brand or franchisor, we may share the information you submit with CyberMark, which provides brandVANTAGE strategy, implementation, support, and managed marketing services for franchise organizations. CyberMark may use the information to respond to and manage your inquiry.
  • At your direction — when you configure an integration (e.g., HubSpot, Calendly) that involves sending data to a third party.
  • Legal compliance — when required by law, court order, or governmental authority, or to protect the rights, property, or safety of KynectLocal, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, or sale of all or substantially all of our assets, provided that the successor entity agrees to be bound by this Privacy Policy.
  • With your explicit consent — for any other purpose, with your prior written consent.

11. Data Retention

Data TypeRetention Period
Active account data (user profiles, business data, content)For the duration of the active subscription, plus 90 days after termination
Audit log entries24 months from creation (configurable per tenant; auto-purged by scheduled job)
Lead and form submission dataDuration of the active subscription; deleted upon account deletion unless legally required to retain
AI usage logs12 months
Request / access logs (structured logs)90 days
Billing records and invoices7 years (legal and tax compliance)
Password reset tokens1 hour (expire automatically)
Refresh tokensInvalidated on use or logout; orphaned tokens purged after 30 days
Bulk import staging data (Redis)Automatically evicted per Redis TTL configuration
Media files (object storage)Deleted when the associated media record is deleted; orphan cleanup run periodically

You may request deletion of your personal data at any time (see Section 14). We will honor deletion requests subject to applicable legal holds and our legitimate interest in maintaining audit records.

12. Security Measures

We implement the following technical and organizational measures to protect your data:

  • Authentication — RS256 JWT access tokens (15-minute expiry) with rotating refresh tokens. Immediate refresh token invalidation on use prevents replay attacks.
  • Password storage — bcrypt hashing with a configurable cost factor (minimum 12 in production).
  • Credential encryption — integration API keys and secrets stored using AES-256-GCM symmetric encryption with per-record key derivation.
  • Transport security — all data transmitted over HTTPS/TLS. HTTP to HTTPS upgrades enforced.
  • Database isolation — all queries are scoped to the authenticated tenant; cross-tenant access is prevented at the application layer.
  • Rate limiting — per-IP and per-user rate limits enforced on all API endpoints, backed by Redis.
  • Security headers — Helmet.js middleware applies standard HTTP security headers (CSP, HSTS, X-Frame-Options, etc.).
  • Audit trail — all material data modifications are written to a tamper-evident audit log.
  • Dependency management — regular dependency updates and security patch reviews.
Security Incidents Despite best efforts, no system is immune to security incidents. If we discover a breach affecting your personal data, we will notify you in accordance with applicable law, generally within 72 hours of becoming aware of the incident for GDPR-covered data.

13. International Data Transfers

KynectLocal operates primarily in the United States. If you access the platform from outside the United States, your data will be transferred to, stored, and processed in the United States and potentially other countries where our sub-processors operate.

For transfers from the European Economic Area, United Kingdom, or Switzerland, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our data processing agreements with sub-processors.
  • The EU–US Data Privacy Framework for sub-processors that are certified under it.

If you have questions about international transfers, contact us using the details in Section 18.

14. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

RightDescription
AccessRequest a copy of the personal data we hold about you.
RectificationRequest correction of inaccurate or incomplete data.
Erasure ("right to be forgotten")Request deletion of your personal data, subject to legal retention obligations.
RestrictionRequest that we limit how we process your data in certain circumstances.
PortabilityRequest a machine-readable export of your personal data.
ObjectionObject to processing based on legitimate interests or for direct marketing purposes.
Withdraw consentWhere processing is based on consent, withdraw that consent at any time.
Lodge a complaintFile a complaint with your local data protection supervisory authority.

To exercise any of these rights, contact us at privacy@kynectlocal.com. We will respond within 30 days (or the timeframe required by applicable law). We may need to verify your identity before fulfilling a request.

If you are a franchisee employee or end user of a brand operating on KynectLocal, you should direct data subject requests to that brand directly, as they are the data controller for that data.

15. California Privacy Rights (CCPA / CPRA)

California residents have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Know — the categories of personal information collected, the purposes for collection, and the categories of third parties with whom it is shared.
  • Delete — request deletion of personal information, subject to exceptions.
  • Correct — request correction of inaccurate personal information.
  • Opt out of sale or sharing — we do not sell or share personal information for cross-context behavioral advertising as those terms are defined under CCPA/CPRA.
  • Limit use of sensitive personal information — we do not use sensitive personal information beyond what is necessary to provide the service.
  • Non-discrimination — we will not discriminate against you for exercising any CCPA/CPRA rights.

To exercise California privacy rights, contact us at privacy@kynectlocal.com or use the contact information in Section 18. We will respond within 45 days as required by law. An authorized agent may submit a request on your behalf with proper written authorization.

Categories of Personal Information Collected (CCPA)

  • Identifiers (name, email, IP address)
  • Commercial information (subscription plans, billing history)
  • Internet or other electronic network activity (request logs, usage data)
  • Professional or employment-related information (role, business affiliation)
  • Geolocation data (city/state level, derived from location profiles)
  • Inferences drawn from the above to create a profile about platform usage

16. Children's Privacy

The KynectLocal platform is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that data. If you believe we may have collected data from a child, contact us at privacy@kynectlocal.com.

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page.
  • Send an email notification to account holders at least 14 days before the changes take effect.
  • Display a prominent notice within the platform admin interface.

Your continued use of the platform after the effective date constitutes acceptance of the updated policy. If you do not agree with any changes, you must cease use of the platform and may request account closure.

18. Contact Us

For questions, concerns, or to exercise your privacy rights, contact us:

KynectLocal Privacy Team Email: privacy@kynectlocal.com
Subject line: "Privacy Request — [Your Name]"

For GDPR-related inquiries from EEA/UK residents, include "GDPR Request" in your subject line.

We aim to respond to all privacy inquiries within 5 business days and to fulfill requests within 30 days (or the applicable legal deadline).